Rundll32 Suspicious Outbound Network Connection Indicative of C2
Detects network connections initiated by a non-Microsoft signed rundll32.exe process. The rule identifies processes named rundll32.exe that are not signed by Microsoft and are communicating over common ports associated with malicious activity, specifically focusing on external IP addresses and multiple connection attempts.
SentinelOne

